Re: TLS handshake issue

2016-03-19 Thread Andrey Fesenko
On Thu, Mar 17, 2016 at 8:18 PM, John Oliver wrote: > dovecot-2.0.9 on CentOS 6.7 > > The system in question is not connected to the Internet, so I can't > copy-and-paste. I have to type anything required :-( > > Brand-new out-of-the-box install with a really minimal

Re: Client-initiated secure renegotiation

2016-03-10 Thread Andrey Fesenko
On Thu, Mar 10, 2016 at 12:30 PM, Osiris wrote: > On 09-03-16 13:14, djk wrote: >> On 09/03/16 10:44, Florent B wrote: >>> Hi, >>> >>> I don't see any SSL configuration option in Dovecot to disable >>> "Client-initiated secure renegotiation". >>> >>> It is advised to

Re: Segmentation fault on doveadm search -A with a huge user base

2016-02-12 Thread Andrey Fesenko
On Sat, Feb 13, 2016 at 1:36 AM, Heiko Schlittermann wrote: > Hi, > > I'm using dovecot 2.2.9 with a director/backend setup. The user base is > about 4711 users currently. > > If I start at one of the directors > > doveadm search -A all savedbefore 5000d > > it

Re: Dovecot (LDAP) quota only if user in backend?

2016-02-08 Thread Andrey Fesenko
On Wed, Feb 3, 2016 at 6:06 PM, Andrey Fesenko <f0and...@gmail.com> wrote: > Hello, > > Is it possible to get the quotas for users served by the backend? > > My env CentOS, dovecot-2.2.10-5.el7, users in LDAP > > > BackendHost may bee backend1.wibble.net backend2.wib

Dovecot (LDAP) quota only if user in backend?

2016-02-03 Thread Andrey Fesenko
Hello, Is it possible to get the quotas for users served by the backend? My env CentOS, dovecot-2.2.10-5.el7, users in LDAP dn: uid=user,ou=mailboxs,dc=wibble,dc=net cn: Account for server mail sn: User objectClass: top objectClass: person objectClass: posixAccount objectClass:

Re: Dovecot (director, lmtp) IPv4/IPv6?

2016-01-29 Thread Andrey Fesenko
On Fri, Jan 29, 2016 at 5:38 PM, Timo Sirainen <t...@iki.fi> wrote: > On 28 Jan 2016, at 12:35, Andrey Fesenko <f0and...@gmail.com> wrote: >> >> Jan 28 13:12:49 mail dovecot[8]: director: Fatal: Invalid director >> port in IPv6-local1 > > b) Append :

Dovecot (director, lmtp) IPv4/IPv6?

2016-01-28 Thread Andrey Fesenko
Hello, I'm build system with two director/proxy and dual stack network (or IPv6-only local services) http://wiki2.dovecot.org/Director say "This also means that a single director ring must use either IPv4 or IPv6 addresses, but not both at the same time." OK All servers have 2 interface (public

Dovecot LDAP host - hostip resolution and alternative

2016-01-28 Thread Andrey Fesenko
dovecot-2.2.10-5.el7, CentOS Linux release 7.2.1511 (Core) Users stored in LDAP, backend name set his hostname (need for TLS on backend) auth: Debug: passdb out: PASS 1 user=mail proxy=yes host=backend starttls=yes hostip=IPv6-public how algorithm choice IP for hostip, and whether it is

Re: CentOS rpm dovecot 2.2.10 auth/db-ldap.c TLS bug/patch

2015-12-03 Thread Andrey Fesenko
On Tue, Dec 1, 2015 at 5:51 PM, Timo Sirainen <t...@iki.fi> wrote: > On 25 Nov 2015, at 15:42, Andrey Fesenko <f0and...@gmail.com> wrote: >> >> Hello, >> CentOS rpm dovecot 2.2.10 сontains bug auth/db-ldap.c TLS (not connect >> LDAP+TLS server ldaps://), exi

CentOS rpm dovecot 2.2.10 auth/db-ldap.c TLS bug/patch

2015-11-25 Thread Andrey Fesenko
Hello, CentOS rpm dovecot 2.2.10 сontains bug auth/db-ldap.c TLS (not connect LDAP+TLS server ldaps://), exist bug/patch https://bugs.centos.org/view.php?id=8267 As far as the correct patch in upstream dovecot quite a lot of changes at this point if there is a correct patch?

LDAP schema for dovecot proxy?

2015-11-10 Thread Andrey Fesenko
Hello, I want to deploy dovecot proxy/director with the backend and authorization in LDAP. Dovecot wiki specifies only what is necessary to apply additional arguments that the scheme would have earned a proxy, but no solid LDAP schema. Is there such a scheme, such as the existing scheme

Proxy with director accept only plain login

2015-10-27 Thread Andrey Fesenko
Hello, i'm test system dovecot (proxy with director) and backend storage, auth LDAP server (user plain passwords) If i use plain auth, work fine. If connect DIGEST-MD5 or CRAM-MD5 proxy not redirect connection (Requested DIGEST-MD5 scheme, but we have a NULL password) ### Frontend